Second deployment phase for Kerberos RC4 hardening begins with the April 2026 Windows security update
Geändert
Services
Windows
Windows updates released April 2026 and later begin the second deployment phase of protections for a Kerberos information disclosure vulnerability (CVE‑2026‑20833). In this phase, domain controllers change default Kerberos ticket behavior for accounts that do not have an explicit Kerberos encryption configuration, shifting to AES‑SHA1-only by default. Environments with remaining RC4 dependencies may experience authentication issues unless those dependencies are remediated or explicitly configured. When this will happen:April 2026 - Enforcement Phase with manual rollback: With installation of the April 2026 Windows security update, default Kerberos behavior changes so domain controllers use AES‑SHA1-only encryption for accounts without explicit encryption type settings, and Enforcement mode is enabled by default on Windows domain controllers. Audit mode remains available as a manual rollb
stayInformednormalMC1279829
The April 2026 Windows security update is now available
Major Change
Geändert
Services
Windows
The April 2026 security update is now available for all supported versions of Windows. We recommend that you install these updates promptly. For more information about the contents of this update, see the release notes, which are easily accessible from the Windows 11 update history page. To learn more about the different types of monthly quality updates, see Windows monthly updates explained. Highlights for the Windows 11, version 25H2 update: This security update includes fixes and quality improvements from KB5079391 (released March 26, 2026 - no longer offered) and KB5086672 (released March 31, 2026). This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. This update expands high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Devices receive th
stayInformednormalMC1278941
Broader Windows Autopatch availability to Microsoft 365 Government Community Cloud (GCC)
Geändert
Services
Windows
Next month, Windows Autopatch will become more broadly available in Government Community Cloud (GCC). Previously, Windows Autopatch was not automatically available for Microsoft 365 G3 and G5 SKUs in GCC. It required the $0 Windows Enterprise (OLS) activation SKU. Now, the OLS SKU is no longer needed. Windows Autopatch is included automatically with:Microsoft 365 G3 GCC Microsoft 365 GCC G5 Microsoft 365 GCC G5 without WDATP/CAS Unified When will this happen:Expected date of launch: May 13, 2026 How this will affect your organization:If you don't use the $0 Windows Enterprise (OLS) activation SKU, you’ll see new Windows Autopatch features in Microsoft Intune next month. These features include update policies for feature, quality, and driver updates, plus enhanced reporting. What you need to do to prepare:No action is needed. New capabilities will be available automatically in Microsoft I
planForChangenormalMC1278920
Support for Office LTSC 2021, and additional apps will end on October 13, 2026
Major Change
Geändert
Services
Microsoft 365 suite
As previously communicated, support for Office LTSC 2021 will end on October 13, 2026. After that date, no further updates, security fixes, or technical support will be available for this version of Office. While the applications may continue to function, using unsupported software could lead to potential security risks, compliance risks, system incompatibilities, and other issues. Support for Visio LTSC 2021 and Microsoft Project LTSC 2021 and several other products will also end on October 13, 2026. Organizations using these products should upgrade as soon as possible to maintain security, compliance, and performance. [How this will affect your organization:] After end of support, Office LTSC 2021 suites and standalones will no longer receive security updates or other fixes, and no technical assistance will be available for devices still running them. Continuing to use unsupported soft
stayInformednormalMC1276259
Windows Deployment Services (WDS): Hands-free deployment hardening (Phase 2)
Major Change
Geändert
Services
Windows
As announced in January 2026, the unattend.xml file used in hands‑free deployment poses a vulnerability when transmitted over an unauthenticated RPC channel. Beginning with the April 2026 security update, the second phase of hardening for CVE-2026-0386 is now in effect. These changes make hands‑free deployment disabled by default to enforce secure behavior. After this update, hands‑free deployment no longer works unless explicitly overridden with registry settings. When will this happen:Starting with the April 2026 security update, Windows Deployment Services (WDS) enforces secure‑by‑default behavior by automatically disabling hands‑free deployment. How this will affect your organization:After installing the April 2026 security update, hands‑free deployment is blocked to prevent unauthenticated access to unattend.xml, enforcing the hardening requirements for CVE-2026-0386. Any workflows
stayInformednormalMC1275343
Hardening administrative actions: Windows imaging, cloning, and auth workflows
Geändert
Services
Windows
Administrative actions are undergoing hardening changes that might require operational change to support your organization’s security posture. With the August 2025 Windows non-security update, devices were hardened against unauthorized attempts to bypass loopback detection. However, if you’ve cloned machines without Sysprep, you might see Kerberos and NTLM authentication failures. This is by design. The recommended solution is to rebuild affected devices using supported imaging methods. A temporary workaround is also available. When will this happen:September 2025 and later: Windows security updates include hardening changes that strengthen the trust boundary between identity, authentication, and User Account Control (UAC). April 2026 and later: Windows security updates include a temporary workaround for machines cloned without Sysprep. This registry-based compatibility option isn’t reco